Skip to content
← All Threat Actors
Cybercrime high Eastern Europe (assessed)

INC Ransom

Ransomware-as-a-Service (RaaS) operation · Financial — ransomware and double extortion

Reports 1
Active Since 2023
Last Reported 22 Jun 2026
Sectors Targeted healthcare, finance, critical-infrastructure

Tactics, Techniques & Procedures (TTPs)

  • Rust-based cross-platform encryptor: Windows and Linux/ESXi builds from a single codebase
  • Updated Veeam DPAPI credential dumper: extracts Veeam backup credentials via Windows DPAPI abuse, modified to bypass AMSI and modern EDR products
  • Initial access via exposed RDP, phishing, and VPN exploitation
  • LOLBin lateral movement: RDP, PsExec, and WMI across domain environments
  • Cobalt Strike for interactive operator access during extended dwell and exfiltration phase
  • Rclone exfiltration to attacker-controlled cloud storage before encryption deployment
  • Possible Osiris ransomware affiliate overlap: Poortry BYOVD driver-based EDR killer and code structural similarities observed

Known Targets

Healthcare organisations (NHS Scotland 2024 — 3TB patient data exfiltrated)Manufacturing and industrial organisationsFinancial servicesTechnology companiesEducation sector

Analyst Notes

INC Ransom has been active since August 2023, reaching 830+ claimed victims by mid-2026 and placing fourth globally by victim count in Q1 2026. The NHS Scotland breach (March 2024) — 3TB of patient data including clinical records — established INC as willing to attack high-profile healthcare targets. The Veeam DPAPI credential dumper is INC's most operationally significant tool: it targets backup administrator credentials that organisations rely on for ransomware recovery, with an AMSI bypass to function against modern endpoint security. Possible Osiris ransomware affiliate overlap (Poortry BYOVD, code similarities) suggests shared tooling across related Eastern European groups.

Also Known As

INC Ransom